Data last synced:
Last updated:
Apple, Inc. settled its potential civil liability for apparent violations of the Foreign Narcotics Kingpin Sanctions Regulations, 31 C.F.R. part 598, agreeing to pay $466,912. Apple appears to have violated the regulations by hosting, selling, and facilitating the transfer of software applications and associated content belonging to SIS, d.o.o., a Slovenian software company previously identified on OFAC's List of Specially Designated Nationals and Blocked Persons as a significant foreign narcotics trafficker. The apparent violations occurred from on or about February 24, 2015 to on or about May 9, 2017.
Penalty Amount
$466,912.00
Enforcement Date
November 25, 2019
Rank in Top Penalties
#143
From on or about February 24, 2015 to on or about May 9, 2017, Apple appears to have violated ยง 598.203 of the FNKSR by hosting, selling, and facilitating the transfer of software applications and associated content owned by SIS, d.o.o. ("SIS"), a Slovenian software company designated on OFAC's SDN List as a significant foreign narcotics trafficker (SDNTK).
On February 24, 2015, the same day OFAC designated SIS and its director and majority owner Savo Stjepanovic pursuant to the Foreign Narcotics Kingpin Designation Act, Apple screened the newly designated parties against its app developer account holder names. Apple's screening tool failed to match the upper case name "SIS DOO" in Apple's system with the lower case name "SIS d.o.o." on the SDN List. Although the address Apple had on file for SIS matched the address published by OFAC, Apple failed to identify SIS as an SDNTK for over two years after the designation. Apple also failed to identify Stjepanovic, whose full name appeared in Apple's records as an "account administrator," because its compliance process at the time screened only individuals listed as "developers," not all account users.
Following the designation, Apple continued to host SIS's apps on the App Store, allowed downloads and sales, received payments from customers downloading the blocked apps, permitted SIS to transfer its apps to two other developers, and remitted funds monthly to SIS. On or about April 17, 2015, Apple facilitated the transfer of a portion of SIS's apps to a second software company incorporated only days after OFAC's designation of SIS, without personnel oversight or additional screening. On or about September 14, 2015, SIS transferred its remaining apps to a third software company, whose owner took over administration of SIS's App Store account and replaced SIS's banking information with his own. After enhancing its screening tool, Apple identified SIS as a potential SDNTK in February 2017 and suspended payments to the account administered by the Third Company. However, Apple continued making payments to the Second Company for the blocked SIS apps transferred in April 2015. In total, Apple made 47 payments associated with the blocked apps and collected $1,152,868 from customers who downloaded SIS apps over 54 months.
The statutory maximum civil monetary penalty applicable in this matter is $74,331,860. OFAC determined that Apple voluntarily self-disclosed the Apparent Violations and that the Apparent Violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, the base civil monetary penalty amount is $576,434. The settlement amount of $466,912 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.
This enforcement action highlights the benefit of comprehensive SDN List screening that utilizes all of the information on the SDN List. Companies should consider OFAC screening and compliance measures that exploit names, addresses, and other identifying information on the SDN List. Compliance measures should also anticipate potential vulnerabilities in a company's compliance program that could allow sanctions evasion and circumvention, and should include preventative measures that alert and react to sanctions evasion warning signs, such as business and employment connections between individuals and entities.
As noted in OFAC's Framework for Compliance Commitments, U.S. companies can mitigate sanctions risk by conducting risk assessments, and exercising caution when doing business with entities that are affiliated with, or known to transact with, OFAC-sanctioned persons or jurisdictions, or that otherwise pose high risks due to their joint ventures, affiliates, subsidiaries, customers, suppliers, geographic location, or the products and services they offer.
As part of its compliance commitments, Apple reconfigured its primary sanctions screening tool to fully capture spelling and capitalization variations and to account for country-specific business suffixes, and implemented an annual review of the tool's logic and configuration. Apple also expanded screening to include not only app developers but also their designated payment beneficiaries and associated banks, updated employee instructions for reviewing potential SDN List matches, and implemented mandatory training for all employees on export and sanctions regulations.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: 90461d4b32ba7db07a94cf31d6736a78480896264ed41f39f6ca3180631f885a